dotgnu-auth
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Auth]Re: [CoreTeam]IDsec meeting


From: Mario D. Santana
Subject: Re: [Auth]Re: [CoreTeam]IDsec meeting
Date: Sat, 01 Dec 2001 02:20:34 -0800

Mike Warren wrote:

> "Mario D. Santana" <address@hidden> writes:
> 
> > Near as I can tell, the basic difference is that Flysolo's data is
> > fetched from repositories and fed to web services by the _client_.
> 
> Is there any way to verify the data? That is, Profile Providers would
> likely be more trustworthy to Web services if they (optionally, at the
> user's request) verified the data in a user's Profile.

Well, Flysolo is really just some libraries to request and mine for user
profile data. A protocol for verifying that data could be built on top of
them, but in the end the requester has to trust somebody who can be
reasonably expected to provide the data. Schemes that claim to avoid this
look bogus to me.

(IDSec seems to explicitly use this concept, not gloss over it.)

mds




reply via email to

[Prev in Thread] Current Thread [Next in Thread]